User centric fraud detection
Abstract
A computer detects fraudulent access to user accounts of a network application. The computer receives user account usage profile information for a plurality of user accounts. Rules are determined, based in part on the user account profile information, that define account usage patterns across two or more user accounts that identify fraudulent user account usage. The computer receives user account usage event information for a plurality of user accounts. Based on the determined rules, the computer identifies fraudulent user account usage patterns in the user account usage event information and transmits a security alert to the user accounts associated with the identified fraudulent user account usage pattern.
Claims
exact text as granted — not AI-modified1 - 5 . (canceled)
6 . A computer program product for detecting fraudulent access to user accounts of a network application, the method comprising:
one or more computer-readable tangible storage media and program instructions stored on at least one of the one or more storage media, the program instructions comprising:
program instructions to receive user account usage profile information for a plurality of user accounts;
program instructions to determine at least one rule, based at least in part on the user account usage profile information, that defines a fraudulent user account usage pattern that includes user account usage events of two or more user accounts;
program instructions to receive user account usage event information for a plurality of user accounts;
program instructions to identify the fraudulent user account usage pattern in the received user account usage event information, based on the determined rules; and
program instructions to transmit a security alert to the user accounts associated with the identified fraudulent user account usage pattern.
7 . A computer program product in accordance with claim 6 , wherein user account usage profile information includes one or more of: user account login ID's, user devices, physical home location, travel frequency, travel locations, and typical usage times.
8 . A computer program product in accordance with claim 6 , wherein received user account usage event information includes one or more of: device identifier, device IP address, a geographic location, and a timestamp.
9 . A computer program product in accordance with claim 6 , wherein the plurality of user accounts are associated with a single user.
10 . A computer program product in accordance with claim 6 , wherein received account usage event information is stored in an event log.
11 . A system for detecting fraudulent access to user accounts of a network application, the method comprising:
one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage media, and program instructions stored on at least one of the one or more storage media for execution by at least one of the one or more processors via at least one of the one or more memories, the program instructions comprising:
program instructions to receive user account usage profile information for a plurality of user accounts;
program instructions to determine at least one rule, based at least in part on the user account usage profile information, that defines a fraudulent user account usage pattern that includes user account usage events of two or more user accounts;
program instructions to receive user account usage event information for a plurality of user accounts;
program instructions to identify the fraudulent user account usage pattern in the received user account usage information, based on the determined rules; and
program instructions to transmit a security alert to the user accounts associated with the identified fraudulent user account usage pattern.
12 . A system in accordance with claim 11 , wherein user account usage profile information includes one or more of: user account login ID's, user devices, physical home location, travel frequency, travel locations, and typical usage times.
13 . A system in accordance with claim 11 , wherein received user account usage event information includes one or more of: device identifier, device IP address, a geographic location, and a timestamp.
14 . A system in accordance with claim 11 , wherein the plurality of user accounts are associated with a single user.
15 . A system in accordance with claim 11 , wherein received account usage event information is stored in an event log.Join the waitlist — get patent alerts
Track US2014380475A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.